CVE-2022-24913

MEDIUM

Java-merge-sort < 1.1.0 - Exposure to Wrong Actor

Title source: rule

Description

Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 20.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-377 CWE-668
Status published

Affected Products (2)

java-merge-sort_project/java-merge-sort < 1.1.0
com.fasterxml.util/java-merge-sort < 1.1.0Maven

Timeline

Published Jan 12, 2023
Tracked Since Feb 18, 2026